Buffer Overflow Vulnerability in Cisco Secure Firewall Software
CVE-2025-20263

8.6HIGH

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20263?

A buffer overflow vulnerability exists in the web services interface of Cisco Secure Firewall ASA and FTD software due to inadequate boundary checks for data inputs. This allows unauthenticated remote attackers to exploit the vulnerability by sending specially crafted HTTP requests. If successfully exploited, this could result in a buffer overflow condition, potentially forcing the affected system to reload and leading to a denial of service. Organizations using these products should take necessary precautions.

Affected Version(s)

Cisco Adaptive Security Appliance (ASA) Software 9.12.3

Cisco Adaptive Security Appliance (ASA) Software 9.8.3

Cisco Adaptive Security Appliance (ASA) Software 9.12.1

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20263 : Buffer Overflow Vulnerability in Cisco Secure Firewall Software